Expand description
The server runtime: how a configuration becomes routers, and how those are served and rebuilt.
Startup is split on the socket boundary, which is what lets a test drive the whole path on an ephemeral port with its own shutdown future instead of a process signal:
runbindsserver.bind_address, installs theSIGHUPhandler, and hands the socket on. It is the whole ofacme-proxy serve.serve_onvalidates the admin configuration and binds that socket too, when[admin]is enabled.serve_on_withdoes everything else — profile resolution, deduplicated signer backends, per-profile filters and validators, TLS, the job registry (every signer’s handlers, notification delivery and the six table sweeps, built bygeneration::job_registry_for), the runner draining it, andaxum::servewith connect info attached.
That assembly is [generation::build_generation], and it is called again on
every reload rather than only at startup — so the two cannot drift, and a
subsystem added to one is added to the other by construction. What a reload
may change, and what it refuses by name, is crate::reload’s to say;
serve_on_with_reloads is where the two meet.
profile— how a generation builds each ACME endpoint.assembly— what a generation hands its profiles, and what outlives it.generation— one generation built, then published: the reload policy.supervisor— the task that serialises reloads.sockets— the three listeners’ binds, plans and announcements.roles— which ofacme,adminandworkerthis process runs.logging— the subscriberserveinstalls, and its reloadable filter.
What it serves sits below it: the endpoint itself is
acme_proxy_protocol::profile::Profile, and the routers each listener serves, with
their shared layers, are acme_proxy_protocol::router.
reload beside it is what a reload may change and what it refuses by
name. An internal crate of the acme-proxy binary, published in lockstep
with it and with no semver promise of its own.
Re-exports§
pub use assembly::Assembly;pub use assembly::GenerationParts;pub use roles::ProcessRole;pub use roles::RoleSet;pub use sockets::check_metrics_config;
Modules§
- assembly
- What one configuration generation hands its profiles (
GenerationParts), and what outlives it (Assembly). What it dials through isacme_proxy_net::egress::Egress. - generation
- One configuration generation: built and validated in full, then published in one uninterruptible run. Startup builds the first; a reload builds and publishes every later one.
- logging
[logging]— resolving the configuration into an installed subscriber, and swapping it on a reload.- profile
- How a configuration generation builds every
Profileit mounts. - reload
- Replacing a running configuration without restarting the process.
- roles
- Which of the server’s three jobs this process does.
- sockets
- The three listeners’ sockets: binding them at startup, planning a rebind on a reload, and announcing one that has come up.
- supervisor
- The one task that serves reload requests for the life of the process.
Functions§
- run
- Binds the configured sockets and runs the server until a shutdown signal
arrives: the whole of
acme-proxy serve. - serve_
on - Assembles and serves the application over an already-bound socket.
- serve_
on_ with serve_onwith all three sockets supplied.- serve_
on_ with_ reloads serve_on_with, serving configuration reloads as well as requests.